Associate Director - Information Security & GRC

Taggd

Gurugram District

On-site

INR 3,500,000 - 6,000,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Taggd is a digital recruitment platform headquartered in Gurgaon seeking an experienced Information Security leader to own security, GRC, and privacy across Taggd and group companies. You will be the primary enterprise contact for security diligence and customer assurance.

You will define information security policies, extend ISO 27001/SOC 2 Type II, drive DPDP readiness with the DPO, and manage audits, risk, and third-party security reviews with stakeholders and customers.

Qualifications

  • 10+ years in information security and GRC, including hands-on cybersecurity, not paper GRC only.
  • Practical depth in at least two of: incident response, identity and access, vulnerability management, cloud security.
  • ISO 27001 program ownership: you have built an ISMS, not only audited one.
  • SOC 2 Type II program or evidence work.
  • Audit lifecycle management: internal and external, including evidence collection and control testing.
  • Hands-on enterprise customer due diligence: security questionnaires, RFPs, and security reviews.
  • DPDP (or equivalent privacy law) in a real operating context.
  • Comfort speaking with enterprise CISOs and security reviewers.

Responsibilities

  • Write and run information security policy across Taggd and group companies.
  • Extend ISO 27001, SOC 2 Type II, and ISO 42001 across Taggd and group companies as needed.
  • Own DPDP readiness with the DPO.
  • Lead TARA customer security questionnaires and RFP security responses: data residency, model-training claims, DPDP, and related due diligence.
  • Build third-party risk management for vendors that touch Taggd and group companies’ data.
  • Run risk assessments. Keep a live risk register, track remediation, and report to stakeholders.
  • Own the audit lifecycle for internal, customer, and certification audits: evidence collection, control testing, and response.
  • Set cybersecurity controls: identity and access, endpoint, network, and cloud. IT implements. You do not run that team.
  • Own identity and access: access reviews, privileged access, joiners / movers / leavers.
  • Own vulnerability and patch posture: the standard, the tracking, the exceptions. IT executes.
  • Own incident response: playbook, severity, who is called, post-incident review.

Skills

Information security
GRC
Incident response
Identity and access
Vulnerability management
Cloud security
DPDP privacy

Job description

Taggd is a digital recruitment platform that provides Ready-to-Hire talent to India Inc. Combining the power of human knowledge and data, Taggd has successfully fulfilled talent mandates of more than 100+ clients and ensured hiring managers' success for half a million jobs from 14+ sectors. With a vision to fulfil 1 million jobs through our talent platform by 2030, we strive to connect people with people, people with companies, and people with opportunities.

For more information, please visit www.taggd.in.

Location: Gurgaon (HQ: M3M Broadway, Sector 71, Gurgaon)

Reports to: CTO

Work mode: 5 days' Work from Office

The role

You own information security, cybersecurity, and GRC for Taggd and group companies, and you are the person enterprise customers talk to when they diligence TARA, Taggd's agentic AI recruitment engine.

You will define the Information Security policies and set the cybersecurity standard (identity, endpoint, network, cloud, logging, incident response). IT runs the estate to the policies & standards. You work with the DPO on privacy, and with Product and Engineering when a customer or auditor asks how TARA handles data, residency, and model use.

More on TARA: https://taggd.in/recruitment-model/tara-ai/

What you will do

  • Write and run information security policy across Taggd and group companies.
  • Extend ISO 27001, SOC 2 Type II, and ISO 42001 across Taggd and group companies as needed.
  • Own DPDP readiness with the DPO.
  • Lead TARA customer security questionnaires and RFP security responses: data residency, model-training claims, DPDP, and related due diligence.
  • Build third-party risk management (TPRM) for vendors that touch Taggd and group companies’ data.
  • Run risk assessments. Keep a live risk register, track remediation, and report to stakeholders.
  • Own the audit lifecycle for internal, customer, and certification audits: evidence collection, control testing, and response.
  • Set cybersecurity controls: identity and access, endpoint, network, and cloud. IT implements. You do not run that team.
  • Own identity and access: access reviews, privileged access, joiners / movers / leavers.
  • Own vulnerability and patch posture: the standard, the tracking, the exceptions. IT executes.
  • Own incident response: playbook, severity, who is called, post-incident review.

What you need

  • 10+ years in information security and GRC, including hands-on cybersecurity, not paper GRC only.
  • Practical depth in at least two of: incident response, identity and access, vulnerability management, cloud security.
  • ISO 27001 program ownership: you have built an ISMS, not only audited one.
  • SOC 2 Type II program or evidence work.
  • Audit lifecycle management: internal and external, including evidence collection and control testing.
  • Hands-on enterprise customer due diligence: security questionnaires, RFPs, and security reviews.
  • DPDP (or equivalent privacy law) in a real operating context.
  • Comfort speaking with enterprise CISOs and security reviewers.
  • Based in Gurgaon / NCR, or willing to work from Taggd HQ.

Nice to have

  • CISA, CISM, CISSP, or CIPP.
  • Hands-on cloud security (AWS or equivalent).
  • ISO 42001.
  • Security review of GenAI or agentic systems.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Associate Director - Information Security & GRC
Associate Director - Information Security & GRC

Talent Hired-the Job Store • Gurugram District, Delhi

On-site
INR 600,000 - 900,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Power Bridge • Arishinakunte

On-site
INR 1,200,000 - 2,400,000
Health insurance
Long-term savings plan with employer’匹
Professional development opportunities
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Project Manager-Info Sec
Project Manager-Info Sec

Acuity Analytics • Gurugram District

On-site
INR 2,500,000 - 4,500,000
Information Security -Project Manager
Information Security -Project Manager

Acuity Analytics • Gurugram District

On-site
INR 2,500,000 - 4,000,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Senior Security & Compliance Lead – Certifications & GRC
Senior Security & Compliance Lead – Certifications & GRC

PETADATA • Hyderabad

On-site
INR 450,000 - 700,000
Assistant Manager - Information Security/ IT GRC
Assistant Manager - Information Security/ IT GRC

KVAT & Co • Navi Mumbai

On-site
INR 1,500,000 - 2,100,000
Flexible work arrangements
IN_Senior Associate_ Governance GRC_Managed Services_Advisory_Gurgaon
IN_Senior Associate_ Governance GRC_Managed Services_Advisory_Gurgaon

Price Waterhouse Cooper LLP • Gurugram District

On-site
INR 1,500,000 - 2,100,000
Assistant Manager - Information Security/ IT GRC
Assistant Manager - Information Security/ IT GRC

KVAT & Co • Mumbai

On-site
INR 1,500,000 - 2,700,000